CVE Feed

    Dashboard / CVE / CVE-2023-21414

    CVE-2023-21414

    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published:Oct 16, 2023
    Last Modified:Nov 21, 2024
    EPS:Oct 16, 2023
    EPSS Score:0.00012
    CVSS Score:7.1

    Affected Products

    Vendor
    Axis
    Product
    A8207-ve Mk Ii
    Vendor
    Axis
    Product
    Axis Os
    Vendor
    Axis
    Product
    M3215
    Vendor
    Axis
    Product
    M3216
    Vendor
    Axis
    Product
    M4317-plve
    Vendor
    Axis
    Product
    M4318-plve
    Vendor
    Axis
    Product
    M4327-p
    Vendor
    Axis
    Product
    M4328-p
    Vendor
    Axis
    Product
    P1467-le
    Vendor
    Axis
    Product
    P1468-le
    Vendor
    Axis
    Product
    P1468-xle
    Vendor
    Axis
    Product
    P3265-lv
    Vendor
    Axis
    Product
    P3265-lve
    Vendor
    Axis
    Product
    P3265-v
    Vendor
    Axis
    Product
    P3267-lv
    Vendor
    Axis
    Product
    P3267-lve
    Vendor
    Axis
    Product
    P3268-lv
    Vendor
    Axis
    Product
    P3268-lve
    Vendor
    Axis
    Product
    P3827-pve
    Vendor
    Axis
    Product
    P4705-plve
    Vendor
    Axis
    Product
    P4707-plve
    Vendor
    Axis
    Product
    Q1656
    Vendor
    Axis
    Product
    Q1656-b
    Vendor
    Axis
    Product
    Q1656-be
    Vendor
    Axis
    Product
    Q1656-ble
    Vendor
    Axis
    Product
    Q1656-dle
    Vendor
    Axis
    Product
    Q1656-le
    Vendor
    Axis
    Product
    Q1961-te
    Vendor
    Axis
    Product
    Q2101-te
    Vendor
    Axis
    Product
    Q3527-lve
    Vendor
    Axis
    Product
    Q3536-lve
    Vendor
    Axis
    Product
    Q3538-lve
    Vendor
    Axis
    Product
    Q3626-ve
    Vendor
    Axis
    Product
    Q3628-ve
    Vendor
    Axis
    Product
    Xfq1656

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High